SearchCZ Česká verze

Working template

Risk assessment outline

Capture the actual risk profile and proportionate controls.

For: Obliged entities under the applicable regime

An outline is neither a completed risk assessment nor an automatic numerical score.

A4 for printing · Word for further editing · created in this browser

Before use

Check current sector rules in the related articles. Add accountable roles, specific sources and steps actually performed. Do not enter unnecessary personal data.

How to complete the template

  1. Products, services, clients and delivery channels

    Segment the portfolio by service, client type and onboarding channel. Record internal data sources and the assessed period.

  2. Geography, payment methods and ownership structures

    For each group describe geographic, payment and ownership factors; do not decide solely by citizenship.

  3. Threats and vulnerabilities supported by evidence

    Assign a misuse scenario, vulnerability and source. Link internal experience to relevant national and sector risk assessments.

  4. Controls, effectiveness and residual risk

    For every risk assign a control, owner and effectiveness test. Explain residual risk after considering controls that actually work.

  5. Approval, change triggers and review

    Record approval, outstanding controls and update triggers. Review a new delivery channel before using it.

Illustrative use

MODEL R-01: new remote channel; vulnerability = acceptance of scans alone. Control = implement a statutory method and failure test. Untested; a plan alone cannot reduce residual risk.

A4 for printing · Word for further editing · created in this browser

When the case is uncertain

A control exists only on paper? Do not count it as effective risk reduction; assign remediation and responsibility.

Legal basis: § 21a a příloha č. 2

V09-2026-10-04 · Redakce eAML.cz

Related guidance